漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Zimbra Collaboration 命令注入漏洞
Vulnerability Description
Zimbra Collaboration是Zimbra公司的一套协作与通信平台。 Zimbra Collaboration 10.1.20之前版本存在命令注入漏洞,该漏洞源于SNMP通知处理期间未正确清理不可信输入,在安装zimbra-snmp包并启用SNMP通知时,未经身份验证的攻击者可以发送特制的SMTP请求,可能导致以Zimbra用户身份执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A